10-Strike Network Inventory Explorer Pro
cpe:2.3:a:10-strike:network_inventory_explorer:*:*:*:*:*:*:*
- 9.31
A privilege escalation vulnerability has been identified in 10-Strike Network Inventory Explorer Pro version 9.31. The issue arises from an unquoted service path in the 'srvInventoryWebServer' service, which runs with LocalSystem privileges. This vulnerability allows attackers to exploit the unquoted path by placing malicious executables in potential path segments, leading to the execution of code with system-level permissions.
Exploitation of this vulnerability could result in unauthorized privilege escalation, allowing attackers to execute code with system-level rights.
The vulnerability can be reproduced by querying the service configuration using the Windows Management Instrumentation Command-line (WMIC) tool. This will reveal the unquoted service path, which can then be exploited by placing a malicious executable in a directory that is part of the path.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.